Home
MEDIUM: 5.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
20.2-25.1
affected
Description
Stored XSS in Discussions in OpenText Content Management CE 20.2 to 25.1 on Windows and Linux allows authenticated malicious users to inject code into the system.
Problem types
CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')
Product status
20.2-25.1
Credits
Hussein Bahmad (NTT Data)
References
support.opentext.com/...henticated&sysparm_article=KB0839121